Questions for the XDR-ENGINEER were updated on : Dec 01 ,2025
[Detection Engineering]
Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted
to a custom prevention rule?
D
[Data Ingestion and Integration]
A new parsing rule is created, and during testing and verification, all the logs for which field data is to
be parsed out are missing. All the other logs from this data source appear as expected. What may be
the cause of this behavior?
C
[Cortex XDR Agent Configuration]
Multiple remote desktop users complain of in-house applications no longer working. The team uses
macOS with Cortex XDR agents version 8.7.0, and the applications were previously allowed by
disable prevention rules attached to the Exceptions Profile "Engineer-Mac." Based on the images
below, what is a reason for this behavior?
A
[Detection Engineering]
During a recent internal purple team exercise, the following recommendation is given to the
detection engineering team: Detect and prevent command line invocation of Python on Windows
endpoints by non-technical business units. Which rule type should be implemented?
B
[Data Ingestion and Integration]
When onboarding a Palo Alto Networks NGFW to Cortex XDR, what must be done to confirm that
logs are being ingested successfully after a device is selected and verified?
A
[Playbook Creation and Automation]
An XDR engineer is configuring an automation playbook to respond to high-severity malware alerts
by automatically isolating the affected endpoint and notifying the security team via email. The
playbook should only trigger for alerts generated by the Cortex XDR analytics engine, not custom
BIOCs. Which two conditions should the engineer include in the playbook trigger to meet these
requirements? (Choose two.)
A,C
[Data Ingestion and Integration]
What is a benefit of ingesting and forwarding Palo Alto Networks NGFW logs to Cortex XDR?
C
[Maintenance and Troubleshooting]
After deploying Cortex XDR agents to a large group of endpoints, some of the endpoints have a
partially protected status. In which two places can insights into what is contributing to this status be
located? (Choose two.)
B,C
[Planning and Installation]
The most recent Cortex XDR agents are being installed at a newly acquired company. A list with
endpoint types (i.e., OS, hardware, software) is provided to the engineer. What should be cross-
referenced for the Linux systems listed regarding the OS types and OS versions supported?
B
[Planning and Installation]
During deployment of Cortex XDR for Linux Agents, the security engineering team is asked to
implement memory monitoring for agent health monitoring. Which agent service should be
monitored to fulfill this request?
D
[Maintenance and Troubleshooting]
When isolating Cortex XDR agent components to troubleshoot for compatibility, which command is
used to turn off a component on a Windows machine?
B
[Cortex XDR Agent Configuration]
Which two steps should be considered when configuring the Cortex XDR agent for a sensitive and
highly regulated environment? (Choose two.)
B,C
[Cortex XDR Agent Configuration]
Some company employees are able to print documents when working from home, but not on
network-attached printers, while others are able to print only to file. What can be inferred about the
affected users’ inability to print?
B
[Detection Engineering]
An analyst considers an alert with the category of lateral movement to be allowed and not needing
to be checked in the future. Based on the image below, which action can an engineer take to address
the requirement?
B
[Post-Deployment Management and Configuration]
Based on the SBAC scenario image below, when the tenant is switched to permissive mode, which
endpoint(s) data will be accessible?
C